Patent · US Active

Advanced persistent threat (APT) detection in a mobile device

US10631168B2 · kind B2 · utility

0Cited by
2References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 28, 2018
Grant dateApr 21, 2020
Priority date
Expiry dateMar 28, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2141
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Advanced persistent threats to a mobile device are detected and prevented by leveraging the built-in mandatory access control (MAC) environment in the mobile operating system in a “stateful” manner. To this end, the MAC mechanism is placed in a permissive mode of operation wherein permission denials are logged but not enforced. The mobile device security environment is augmented to include a monitoring application that is instantiated with system privileges. The application monitors application execution parameters of one or more mobile applications executing on the device. These application execution parameters including, without limitation, the permission denials, are collected and used by the monitoring application to facilitate a stateful monitoring of the operating system security environment. By assembling security-sensitive events over a time period, the system identifies an advanced persistent threat (APT) that otherwise leverages multiple steps using benign components. Once an APT has been detected, a mitigation action (e.g., terminating the malicious process) is undertaken.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.